cbcvebase.
CVE-2020-24394
published 2020-08-19

CVE-2020-24394: In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL…

high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 5.7.6-1 (bookworm)linux 5.7.6-1 (bookworm)
linuxlinux_kernel< 5.7.85.7.8
linuxlinux_kernel>= 0 < 5.7.6-15.7.6-1
linuxlinux_kernel>= 0 < 5.7.6-15.7.6-1
linuxlinux_kernel>= 0 < 5.7.6-15.7.6-1
linuxlinux_kernel>= 0 < 5.7.6-15.7.6-1
linuxlinux_kernel>= 0 < 4.15.0-115.1164.15.0-115.116
linuxlinux_kernel>= 0 < 5.4.0-45.495.4.0-45.49
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.4.91-11_on_cbl_mariner_1.0
opensuseleap
oraclesd-wan_edge
paloaltopan-os
starwindsoftwarestarwind_virtual_san

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv7.8HIGH